Updated on 2026-07-21 GMT+08:00

Revoking Permissions of a Database Account

Function

This API is used to revoke permissions of a database account.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
  • If you are using role/policy-based authorization, see Permissions and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

rds:databasePrivilege:revoke

write

instance

- g:EnterpriseProjectId

- g:ResourceTag/<tag-key>

-

-

Constraints

  • This operation cannot be performed when the DB instance is in any of the following statuses: creating, changing instance class, changing port, or abnormal.
  • The permissions of system accounts and the root account cannot be revoked.

URI

  • URI format

    DELETE /v3/{project_id}/instances/{instance_id}/db_privilege

  • Parameter description
    Table 1 Parameters

    Parameter

    Mandatory

    Description

    project_id

    Yes

    Definition

    Project ID of a tenant in a region.

    Constraints

    The value cannot be empty.

    Range

    To obtain the value, see Obtaining a Project ID.

    Default Value

    N/A

    instance_id

    Yes

    Definition

    Instance ID.

    Constraints

    The value cannot be empty.

    Range

    You can obtain the value of this parameter from id in Table 4 by calling the API for querying DB instances.

    Default Value

    N/A

Request Parameters

Table 2 Parameters

Parameter

Mandatory

Type

Description

db_name

Yes

String

Definition

Database name.

Constraints

N/A

Range

You can obtain the value of this parameter from name in Table 3 by calling the API for querying databases.

Default Value

N/A

users

Yes

Array of objects

Definition

Account information.

For details, see Table 3.

Constraints

A maximum of 50 accounts are supported.

Table 3 users field data structure description

Parameter

Mandatory

Type

Description

name

Yes

String

Definition

Username of the database account.

Constraints

N/A

Range

You can obtain the value of this parameter from name in Table 3 by calling the API for querying database users.

Default Value

N/A

schema_name

Yes

String

Definition

Schema name in the database.

Constraints

N/A

Range

You can obtain the value of this parameter from schema_name in Table 3 by calling the API for querying database schemas.

Default Value

N/A

Example Request

Revoke permissions of an account in the db1 database.
DELETE https://{Endpoint}/v3/8b3d99b2fb1148c69be8fe37bb896f27/instances/51986c9a48df43839a3ba300d6c5e91fin03/db_privilege

{ 
  "db_name" : "db1", 
  "users" : [ { 
    "name" : "user1", 
    "schema_name" : "schema1" 
  } ] 
}

Response

  • Normal response
    Table 4 Parameters

    Parameter

    Type

    Description

    resp

    String

    Definition

    Calling result.

    Range

    Returns successful if the calling is successful, or returns failed if the calling fails.

Status Code

Error Code

For details, see Error Codes.